Two courses. Two audiences.
SCOR Associate (4 Hours)
Send your SOC analysts, satellite operators, engineers, program managers, and risk staff.
They return with:
- The mindset: defense measured by what every move costs the adversary
- The method: METEORSTORM, the Resilient Cyber Operations framework, run end to end
- The tools: a standardized taxonomy and ontology their platforms can ingest the same week
- 4 CPE credits
SCOR Practitioner (8 Hours)
Send your IR leads, security operations, satellite operations, and risk management, together.
They return with:
- The mindset: defense measured by what every move costs the adversary
- The method: METEORSTORM, the Resilient Cyber Operations framework, run end to end
- The tools: a standardized taxonomy and ontology their platforms can ingest the same week
- The reflexes: a confirmed incident triaged, contained, and recovered under a clock, with the scores to prove it
- 8 CPE credits
Three reasons to send your staff to both
01One partner for workforce development and tooling: D2 Team CORP
D2 Team CORP is a 501(c)(3) workforce development and tooling partner operating inside the converged commercial, government, and academic space community. That position is what makes high impact, low cost workforce solutions possible: content built and refined inside the community it serves, subsidized member rates, and open source tooling your teams keep, and directly shape, after the session ends.
02Reflexes are built on a digital twin: Zendir
Incident response is a reflex, and reflexes are built through repetition against realistic consequences. The Zendir digital twin gives your crew a flying spacecraft to defend: live telemetry, real orbital behavior, real consequences, and zero risk to your platform. That is how cyber resilience moves from a document your organization owns to a reflex your people have.
03A 360 degree view of the fight: Proof Labs
Proof Labs brings operational, on-orbit defense experience into the instruction, developing a 360 degree view of the space platform: how an adversary targets it (contextualized threat modeling), how the response runs when they do (incident response preparation), and how the fight is turned back on them (adversary management).
This is workforce development and tooling.
Your people return with tooling: a standardized taxonomy and ontology that can be published as a machine-tag set your threat intelligence platform can ingest the same week, and the method to keep producing entries in it. The Practitioner cohort sends a team home with the ideas and reflexes to update your incident response plan and playbooks. And because everything runs on a provided scenario platform, your architecture, telemetry, and vulnerabilities never enter the room. Only reflexes, ideas, and inspiration leave it.
Pentagon of Pain
Five mastery areas. One outcome: detect, disrupt, deter. Select an area.
METEORSTORM
METEORSTORM covers the ground, user, link, and space segments, and also the aquatic, aerial, and deep space environments. When a merger, an acquisition, or a new market strategy takes your organization toward cislunar, maritime, or drone operations, your staff and your data model come with you: no expensive re-upskilling, no framework migration.
And you do not have to choose METEORSTORM over other frameworks: the analytic layer normalizes past, present, and future frameworks into the same standardized taxonomy and ontology, without building a new taxonomy for each.
Five functions run in order on one data model. Each function builds one mastery area. Select one.
Your annual incident response exercise, performed and documented
The Practitioner course includes a second four-hour session that is a conducted incident response exercise: your crew responds to a confirmed incident under a clock, and comes back with the experience, the scores, and the takeaways to update your incident response plan and playbooks.
Sessions, September to October 2026
SCOR Associate (4 Hours)
Tuesdays, 13:00 to 17:00 ET. Complete in one session. 15 seats per date.
| Session | Date |
|---|---|
| Session 1 | 8 Sep 2026 |
| Session 2 | 15 Sep 2026 |
| Session 3 | 22 Sep 2026 |
| Session 4 | 29 Sep 2026 |
| Session 5 | 6 Oct 2026 |
SCOR Practitioner (8 Hours)
Wednesday and Thursday, 13:00 to 17:00 ET. Both parts in the same week. 15 seats per cohort.
| Cohort | Part One (Wed) | Part Two (Thu) |
|---|---|---|
| Cohort 1 | 9 Sep 2026 | 10 Sep 2026 |
| Cohort 2 | 16 Sep 2026 | 17 Sep 2026 |
| Cohort 3 | 23 Sep 2026 | 24 Sep 2026 |
| Cohort 4 | 30 Sep 2026 | 1 Oct 2026 |
| Cohort 5 | 7 Oct 2026 | 8 Oct 2026 |
Send fifteen.
Every session caps at 15 seats. The organizations that get the most from this program reserve a full session and send security operations, satellite operations, engineering, and risk management through the door together. Preregister through the Center of Excellence and tell us you want all fifteen.
Center of Excellence: Associate Center of Excellence: Practitioner


